XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.8 and 16.3.0RC1.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Sep 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 |
Tue, 13 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xwiki xwiki
|
|
CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xwiki xwiki-platform
|
Xwiki xwiki
|
Mon, 12 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:xwiki:xwiki-platform:16.0.0-rc-1:*:*:*:*:*:*:* |
cpe:2.3:a:xwiki:xwiki-platform:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-31T15:24:20.271Z
Updated: 2024-08-13T13:36:59.723Z
Reserved: 2024-07-24T16:51:40.948Z
Link: CVE-2024-41947
Vulnrichment
Updated: 2024-07-31T15:58:30.116Z
NVD
Status : Analyzed
Published: 2024-07-31T16:15:04.540
Modified: 2024-09-06T20:46:01.477
Link: CVE-2024-41947
Redhat
No data.